BIT-ghost-2026-103288

See a problem?
Import Source
https://github.com/bitnami/vulndb/tree/main/data/ghost/BIT-ghost-2026-103288.json
JSON Data
https://api.osv.dev/v1/vulns/BIT-ghost-2026-103288
Aliases
Published
2026-10-09T10:45:07Z
Modified
2026-10-09T12:10:38Z
Summary
Ghost 5.9.0 before 6.44.1 Authorization Bypass via Comment Like
Details

Ghost, an open-source publishing platform, contains an input validation flaw in its comment like feature in versions from 5.9.0 before 6.44.1. An authenticated member can delete comment likes or dislikes belonging to other users that they are not authorized to delete, resulting in an authorization bypass and unauthorized modification of comment engagement data.

Database specific
{
    "cpes": [
        "cpe:2.3:a:ghost:ghost:*:*:*:*:*:node.js:*:*"
    ],
    "severity": "High"
}
References

Affected packages

Bitnami / ghost

Package

Name
ghost
Purl
pkg:bitnami/ghost

Severity

  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X CVSS Calculator

Affected ranges

Type
SEMVER
Events
Introduced
5.9.0
Fixed
6.44.1

Database specific

source
"https://github.com/bitnami/vulndb/tree/main/data/ghost/BIT-ghost-2026-103288.json"